VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 83 of 277
  • CVE-2023-48363MedFeb 13, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime…

  • CVE-2023-6536MedFeb 7, 2024
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial…

  • CVE-2023-6535MedFeb 7, 2024
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial…

  • CVE-2023-6356MedFeb 7, 2024
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a…

  • CVE-2023-6683MedJan 12, 2024
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference.…

  • CVE-2023-48697MedDec 5, 2023
    risk 0.42cvss 6.4epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to memory buffer and pointer vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2023-31018MedNov 2, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

  • CVE-2023-46239HigOct 31, 2023
    risk 0.42cvss 7.5epss 0.01

    quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil pointer dereference (leading to a panic)…

  • CVE-2023-38712MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on…

  • CVE-2023-38711MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr payload with ID_FQDN, a NULL pointer dereference causes a crash and restart of the pluto daemon. NOTE: the earliest affected…

  • CVE-2021-40266MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.

  • CVE-2021-40264MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.

  • CVE-2020-18378MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.

  • CVE-2020-36138HigAug 11, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).

  • CVE-2023-37456MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.00

    The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

  • CVE-2023-33307MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.

  • CVE-2023-33306MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.

  • CVE-2023-24938MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.02

    Windows CryptoAPI Denial of Service Vulnerability

  • CVE-2023-1667MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.01

    A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.

  • CVE-2023-28484MedApr 24, 2023
    risk 0.42cvss 6.5epss 0.01

    In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.